Published: July 5, 2025
17
197
2.0k

In the past years, I reported dozens of security vulnerabilities in various COD games to activision. None of them ever got fixed, at least not until someone else started exploiting them in the wild. You don't care about security. You only care about publicity.

Where did that lead us to? Me getting a C&D for trying to make the games more secure on my own... Wouldn't be surprised if I already reported the WW2 vulnerability that's currently being exploited.

@momo5502 ah yes, the good old shitty companies C&D'ing security researchers, a tale as old as time. nice of you that you reported stuff for so long even without them fixing/ acknowledging stuff

@pr0me They acknowledged it, they paid me. Makes the situation even weirder...

@momo5502 The best way to get them fixed is just to release them into the wild. Those companies don't care unless they are losing money

@KFluffy3 Honestly, as weird as it sounds, that's probably the way to get them fixed with the least impact for users

@momo5502 idk how true it really is but i also saw that the RCE exploits also aren't against TOS for Microsoft which is wild, they're fine with this which isn't a shock with how they're acting lately maybe they'll tell COD players to use AI to express their feelings too lmao

@Scoomfie Luckily, in the EU, we have the Cyber Resilience Act, which dictates how you have to deal with vulnerabilities if you want your product to be sold in the EU. Regardless of what TOS say.

@momo5502 Sorry to hear that, this has been going on since BLOPS2 on PC and I remember really wanting to snag that game but hearing of the exploits going on in that game....

@randomoosebrain Don't be sorry for me, I haven't touched COD in the last 2 years. Be sorry for the users getting hacked.

@momo5502 Endlessly triggering when a person chooses what I see as the moral route of responsible disclosure and it ends up ignored. There needs to be real accountability for this type of thing. Appreciate your effort.

@Tilted_Tom Well, to be fair. I also did it because they still paid me for reporting them. So I'm probably not the hero people think I am. But I don't have to. The real question is why pay me and not fix them?

@momo5502 The worst thing is, is that the Gamepass build appears to be older than Steam. Double XP bonus isn't present, multiplayer is fully P2P (different version didn't warrant setting up new dedis), throwback perks are missing, Local Play doesn't work and S Drops don't work correctly.

@momo5502 I made a public video on MW3 exploit almost a year ago, it still works. At least they don't sell that game anywhere.

@momo5502 It was like this with the vulns in the souls games, too.

@momo5502 Nah man, Activision is busy recoloring old assets to makes black ops 7, no time to patch anything, that's against the company's philosophy

@momo5502 White hat mentality

@momo5502 These companies are incorrigable. Giving zero fucks outside of their degenerate money making tactics. The irony is, if they did better jobs and had better leaders, producing a better performing product, they'd naturally make a whole lot more money

@momo5502 what a gut punch.

@momo5502 So easy for them to do so quick for WWII but not black ops 3, okay then 🤷‍♂️

@momo5502 Most of cod players (the one spending all the money anyway) are too stupid to care, and at most, will be outraged untill the next 30€ crossover character drops.

@momo5502 Do other games have issues this severe? I’ve heard of big games like GTA leaking ip addresses but full pc access? What is Activision doing?

@momo5502 One man army vs big greedy ass company

Share this thread

Read on Twitter

View original thread

Navigate thread

1/23